| CVE-2026-6286 | 7.2 | — | — | — | — | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site S | 9d ago |
| CVE-2026-14558 | 7.2 | — | — | — | — | The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialise | 9d ago |
| CVE-2026-77365 | 7.2 | — | — | — | — | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress i | 9d ago |
| CVE-2026-76053 | 7.2 | — | — | — | — | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored | 9d ago |
| CVE-2026-18978 | 7.2 | — | — | — | — | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all v | 9d ago |
| CVE-2026-18324 | 7.2 | — | — | — | — | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stor | 9d ago |
| CVE-2026-75417 | 7.2 | — | — | — | — | A SQL injection vulnerability was found in YzmCMS 7.5. | 9d ago |
| CVE-2026-54718 | 7.2 | — | — | — | — | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. | 9d ago |
| CVE-2026-36102 | 7.2 | — | — | — | — | An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated admin | 9d ago |
| CVE-2026-78276 | 7.2 | — | — | — | — | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | 10d ago |
| CVE-2026-78271 | 7.2 | — | — | — | — | Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions. | 10d ago |
| CVE-2026-19223 | 7.2 | — | — | — | — | The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowi | 10d ago |
| CVE-2026-13415 | 7.2 | — | — | — | — | The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one | 10d ago |
| CVE-2026-71171 | 7.2 | — | — | — | dell / cloud disaster recovery | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used | 10d ago |
| CVE-2026-47836 | 7.2 | — | — | — | vmware / spring cloud config | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN re | 11d ago |
| CVE-2026-81031 | 7.2 | — | — | — | — | IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the reques | 11d ago |
| CVE-2026-80233 | 7.2 | — | — | — | — | CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerab | 11d ago |
| CVE-2026-18331 | 7.2 | — | — | — | — | The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress | 11d ago |
| CVE-2026-74851 | 7.2 | — | — | — | — | The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked | 11d ago |
| CVE-2026-19760 | 7.2 | — | — | — | — | The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi | 11d ago |
| CVE-2026-45019 | 7.2 | — | — | — | — | Chainlit is a Python framework for building production-ready conversational AI applications. | 11d ago |
| CVE-2026-75498 | 7.2 | — | — | — | — | Webkul QloApps does not validate request parameters before a database query. | 12d ago |
| CVE-2026-75497 | 7.2 | — | — | — | — | Webkul QloApps does not validate request parameters before a database query. | 12d ago |
| CVE-2026-75496 | 7.2 | — | — | — | — | Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file | 12d ago |
| CVE-2026-75971 | 7.2 | — | — | — | — | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulne | 12d ago |
| CVE-2026-18328 | 7.2 | — | — | — | — | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM- | 12d ago |
| CVE-2026-18323 | 7.2 | — | — | — | — | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stor | 12d ago |
| CVE-2026-56703 | 7.2 | — | — | — | — | Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is | 12d ago |
| CVE-2026-71943 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. | 13d ago |
| CVE-2026-71942 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. | 13d ago |
| CVE-2026-71941 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. | 13d ago |
| CVE-2026-71940 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE func | 13d ago |
| CVE-2026-71939 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE funct | 13d ago |
| CVE-2026-71938 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. | 13d ago |
| CVE-2026-71937 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. | 13d ago |
| CVE-2026-71936 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. | 13d ago |
| CVE-2026-71935 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. | 13d ago |
| CVE-2026-71934 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. | 13d ago |
| CVE-2026-71931 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. | 13d ago |
| CVE-2026-71930 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. | 13d ago |
| CVE-2026-71929 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. | 13d ago |
| CVE-2026-71928 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. | 13d ago |
| CVE-2026-71927 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. | 13d ago |
| CVE-2026-71926 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. | 13d ago |
| CVE-2026-71925 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. | 13d ago |
| CVE-2026-71924 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. | 13d ago |
| CVE-2026-71923 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. | 13d ago |
| CVE-2026-71919 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. | 13d ago |
| CVE-2026-71918 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. | 13d ago |
| CVE-2026-71917 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. | 13d ago |
| CVE-2026-71916 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. | 13d ago |
| CVE-2026-71915 | 7.2 | — | — | — | — | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. | 13d ago |
| CVE-2026-71913 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. | 13d ago |
| CVE-2026-71912 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. | 13d ago |
| CVE-2026-71911 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. | 13d ago |
| CVE-2026-71910 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. | 13d ago |
| CVE-2026-71909 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. | 13d ago |
| CVE-2026-71908 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. | 13d ago |
| CVE-2026-71907 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. | 13d ago |
| CVE-2026-71906 | 7.2 | — | — | — | — | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. | 13d ago |